Skip to content
Secantra

Solution · ISO/IEC 27001:2022

An ISMS you can show the auditor, not just describe

ISO/IEC 27001:2022 requires a managed information-security management system — clauses 4 to 10 — supported by the 93 Annex A controls. Secantra holds the risk assessment, applicability decisions, controls and evidence in one record so certification and surveillance audits run from the system, not from a folder.

At a glance
Instrument
ISO/IEC 27001:2022 (with ISO/IEC 27002:2022 guidance)
Applies from
Voluntary certification; 2013 certificates transition to 2022 by 31 October 2025
Who
Any organisation seeking certification or customer assurance; often demanded in procurement
Supervision
Accredited certification bodies; stage 1 / stage 2 and annual surveillance audits

Mapping

What ISO 27001 asks — and where it lives in Secantra

Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.

What ISO 27001 asks — and where it lives in Secantra
ISO 27001 areaClauseWhat is expectedIn SecantraStatus
Risk assessment & treatment6.1.2, 6.1.3, 8.2–8.3Identify, analyse and evaluate information-security risks; select controls; produce a treatment plan.Risk register with structured assessment, treatment plans and formal acceptance — linked to the assets and controls concerned.LIVE
Statement of Applicability6.1.3 d)List the necessary controls, whether implemented, and justify inclusions and exclusions.Applicability per requirement with reasons is the SoA data; the control library records implementation status.LIVE
Annex A controlsA.5–A.893 controls across organisational, people, physical and technological themes.Controls from templates or your own; evidence with recency rules; findings for gaps; posture per theme.LIVE
Documented information7.5Create, update and control the documents and records the ISMS requires.Governance documents with templates, revisions and review / approval workflows; files with retention.LIVE
Asset inventory & ownershipA.5.9, A.5.10An inventory of information and associated assets, with owners and acceptable-use rules.The CMDB with owners, criticality and structural relationships; quality workspace for the gaps.LIVE
Internal audit & management review9.2, 9.3Planned internal audits and management reviews at planned intervals, with recorded results.Assessment cycles against adopted requirements; audit-ready record of decisions. Reviews scheduled with reminders.PARTLY

How it runs

A ISO 27001 programme in Secantra

  • 01

    Adopt ISO/IEC 27001:2022

    Pin the published version; scope the ISMS; decide applicability per clause and control.

  • 02

    Map assets and owners

    Information assets, the services and solutions they belong to, and the accountable owners.

  • 03

    Assess risk, attach controls and evidence

    Risk register drives control selection; evidence with recency rules keeps it current between audits.

  • 04

    Show the auditor the record

    SoA data, control coverage, evidence and findings — and generated reports from the record: framework status, risk register, executive summary.

Questions ISO 27001 teams ask

Does Secantra generate the Statement of Applicability document?

It holds the SoA data — applicability with justification and control status — from which the document is produced; the format is yours or your auditor's.

We are certified against the 2013 edition — what changes?

The 2022 controls are a different published version; you transfer the adoption explicitly and the superseded one stays as history.

Can auditors get read access?

Role-based access with tenant scope is how the platform works; how you grant an auditor a scoped, time-bounded role is an administrative setting.

See it on your own frameworks

A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.